Firewall Advice

Soldato
Joined
19 Apr 2009
Posts
3,159
Install the ASDM on the PIX and itll make life 100x easier.

But I would recommend a ASA 5505 if your looking to buy a new one.
 
Associate
OP
Joined
3 May 2009
Posts
805
Holy thread revival!!

well ive been tearing my hair out and im still looking, each manufacturer has different specs, does anybody know a good way of calculating whats currently going through our pix?

I have been looking at the xtm 505 and can get one with 3 years subscription for £1500

http://www.watchguard.com/products/xtm-5/compare.asp?p1=xtm505&p2=xtm510&p3=xtm520&p4=xtm530

our reseller reckons we would need a 520/530 and that he puts a 505 in for 30 people businesses, surely hes having me on with sales patter?
 
Soldato
Joined
17 Oct 2002
Posts
3,941
Location
West Midlands
If it's UTM you want at a decent price point, aswell as built in IPSEC/SSL VPN support i would go for the Fortigate.

As mentioned above the 80c is your best fit.

http://www.fortinet.com/products/fortigate/80C.html

I normally sit in the Cisco camp but they cant compete at this level in terms of bang for buck.

Im not familiar with the current Watchguard portfolio but they havent done a bad job in the past.
 
Associate
OP
Joined
3 May 2009
Posts
805
If it's UTM you want at a decent price point, aswell as built in IPSEC/SSL VPN support i would go for the Fortigate.

As mentioned above the 80c is your best fit.

http://www.fortinet.com/products/fortigate/80C.html

I normally sit in the Cisco camp but they cant compete at this level in terms of bang for buck.

Im not familiar with the current Watchguard portfolio but they havent done a bad job in the past.

it says the 80c is branch office? This firewall is mainly going to sit on our internet line which will have a 50mb virgin broadband connectiong into it, will it handle it? the 750mbps throughput looks fine but im just wary that its advertised as branch office.
 
Associate
Joined
29 Dec 2003
Posts
2,039
Location
Newcastle upon Tyne
Holy thread revival!!

well ive been tearing my hair out and im still looking, each manufacturer has different specs, does anybody know a good way of calculating whats currently going through our pix?

I have been looking at the xtm 505 and can get one with 3 years subscription for £1500

http://www.watchguard.com/products/xtm-5/compare.asp?p1=xtm505&p2=xtm510&p3=xtm520&p4=xtm530

our reseller reckons we would need a 520/530 and that he puts a 505 in for 30 people businesses, surely hes having me on with sales patter?

Nope, your reseller is telling the truth. On a 50Mbps Virgin connection your going to need something a bit meatier than an XTM 505. If you have 200 users your definitely going to need at least a 520 if you will be turning on the Content Filtering and IPS. At work we usually supply WatchGuards but have recently put in our first SonicWALL and they are not bad either.

Your looking at around £2290 for the 520 w/ 1-yr LiveSecurity and around £3230 for a 520 w/ 1-yr Security Bundle. The closest SonicWALL to the XTM 520 is the NSA 2400, these are around £1560 for the base model 2400 or around £2310 for the TotalSecure bundle (these prices are based on the RRP, taking off the usual Partner discount and adding 10% margin for your reseller)

If you have any questions about the WatchGuards feel free to drop me a mail via trust - I wouldn't feel confident answering any in depth questions about the SonicWALL's though, I'm very new to them.
 
Man of Honour
Joined
30 Jun 2005
Posts
9,515
Location
London Town!
If it's UTM you want at a decent price point, aswell as built in IPSEC/SSL VPN support i would go for the Fortigate.

As mentioned above the 80c is your best fit.

http://www.fortinet.com/products/fortigate/80C.html

I normally sit in the Cisco camp but they cant compete at this level in terms of bang for buck.

Im not familiar with the current Watchguard portfolio but they havent done a bad job in the past.

The fortigates are exceptionally high performance and feature rich for the money, I don't like the GUI or the CLI personally but it's friendly for inexperienced users (which is probably why I don't like it, it's not powerful enough).

Juniper still make the best firewalls available in this market, full stop, no question. But you pay a price and they're firewalls first, dial in VPN, web filtering and such are best done by different boxes.
 
Man of Honour
Joined
30 Jun 2005
Posts
9,515
Location
London Town!
it says the 80c is branch office? This firewall is mainly going to sit on our internet line which will have a 50mb virgin broadband connectiong into it, will it handle it? the 750mbps throughput looks fine but im just wary that its advertised as branch office.

It'll be fine, the 80C is plenty powerful unless you have 100Mbit+ WAN links...
 
Back
Top Bottom